Vulnerability Details CVE-2025-49217
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49213 but is in a different method.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 73.4%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2025-49217
-
cpe:2.3:a:trendmicro:trend_micro_endpoint_encryption:-
-
cpe:2.3:a:trendmicro:trend_micro_endpoint_encryption:6.0.0.3204
-
cpe:2.3:o:microsoft:windows:-